Trust this desk in plain language
Desk charter
Operator identity without doxxing. Practices you can hold us to — not a promise of publication or legal immunity.
- What we accept
- Documents, media, and short sealed messages of public-interest concern. We take source protection seriously. We do not solicit crime, child sexual abuse material, or threats of violence.
- What we decline
- Spam, malware bombs, pure private disputes with no public stake, and anything we cannot assess safely. Decline does not always produce a reply.
- Response time
- Best-effort review, typically within a few days to two weeks when the desk is active. Not 24/7. No SLA. Silence is not confirmation of receipt beyond your local receipt file.
- Languages
- Desk review primarily in English. The public site UI is multilingual; sealed content in other languages may take longer or need trusted help to assess.
- Jurisdiction posture
- Operators and hosting sit under real-world law. Ciphertext on disk can still be seized. We do not claim extraterritorial immunity. Prefer Tor for network-level risk reduction.
- Follow-up
- Optional sealed thread after review (off by default). If opened, you use your offline receipt — no account. We never ask you to re-upload the private receipt key.
- Contact (low sensitivity)
- Operational mail: @SafeDepositOrg (low-sensitivity public contact · sealed drop for tips). Official X (corroboration / public updates — not for high-risk tips): @SafeDepositOrg. Do not put high-risk tips in ordinary email or DMs.
What happens after you submit
- Your browser seals the package to the published operator public key(s). The server stores ciphertext only (plus blind metadata: id, size, expiry, content commitment).
- You receive a receipt JSON in the browser. Download it offline. It holds the deposit id, content commitment, receipt token, and optional follow-up private key.
- The deposit sits until an operator downloads ciphertext offline and decrypts with a key that is not on the upload host (by design).
- Review is human and discretionary. There is no automatic publication, no guaranteed story, and no legal representation.
- If a sealed follow-up channel opens later, check receipt status with the same file. Clear browser data on shared machines.
- Deposits auto-expire after the configured TTL if not handled. Treat expiry as normal hygiene, not a threat signal by itself.
You will not get an email confirmation. The receipt is your only portable proof of what you uploaded.
Threat-model honesty — protect / do not protect
What this design aims to protect
- Content confidentiality against a compromised or seized upload server (no deposit private key on host).
- Passive network observers of TLS/onion payloads (ciphertext in transit and at rest on the origin).
- Submitter accounts and marketing trackers (none by design).
- Casual phishing that reuses branding but not the published key fingerprint (if you verify).
- Bulk abuse via proof-of-work and size limits (best-effort).
What this does not protect
- Compromised devices — malware, screen capture, evil USB, workplace MDM.
- Bad OPSEC — real names in filenames, personal accounts in the same session, clearnet habit patterns.
- Global traffic analysis — Tor helps; it is not absolute against a global passive adversary.
- Coerced or malicious operators who hold the offline private key can decrypt deposits they obtain.
- Legal process against people, hosts, or canaries in jurisdictions that compel silence.
- Physical safety or retaliation after disclosure — encryption is not a bodyguard.
This page is the short public honesty layer. Prefer the protect / do-not-protect list above plus key verification and the canary for operational trust checks.
Canary as a dead-man signal
The warrant canary states that, as of its publication date, the operator has not received secret compulsory process of the kind described in the statement. It is a transparency ritual, not courtroom proof.
- Last signed / published — when the public statement was last renewed.
- Next expected — if the date passes without renewal, treat the canary as expired and re-verify out of band.
- Signature — when present, a minisign signature lets you check integrity offline with the published public key.
Expired canary ≠ automatic proof of compromise. It may mean legal pressure, ops failure, or forgetfulness. Combine with key verification and a trusted onion.